NIST SP 800-92
Log Infrastructure

NIST SP 800-92 NISTSP92-3: Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance

Design and operate the log management infrastructure per NIST SP 800-92 Chapter 3 (Log Management Infrastructure) + Chapter 5 (Operational Processes). Log management infrastructure architecture per Section 3.2: (a) tiered architecture covering generation + collection + storage + analysis + reporting, (b) high-availability across collection and storage tiers with documented RTO/RPO, (c) capacity sizing per Section 3.4 with documented log volume forecasting + growth model + headroom planning. Centralised log collection per Section 3.2.2: forwarders or agents (host-installed + sidecar + agentless cloud + tap) deliver to one or more central log management systems + minimise local log retention to reduce attacker advantage. Log transport security per Section 5.3: encrypted in transit (TLS preferred + IPsec + or equivalent), authenticated source + destination, integrity validation, queue/buffer for network outages with replay-on-recovery. Log forwarding agents and health monitoring per Section 5.4: monitor agent liveness + version + configuration drift + delivery success rate + back-pressure + queue depth + with alerting on agent silence (silent failure is the most common log-management failure mode). SIEM and detection platform governance: documented platform owner + platform SLA + correlation rule lifecycle + analyst onboarding + tuning cadence + use-case coverage per MITRE ATTandCK + integration with case management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 88 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • AWWA-3.1 Network Segmentation
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-27 Network security management

ISO/SAE 21434 · 3 controls

  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-27 Network security management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-06 Network security and segmentation
  • FFIEC-09 Encryption and key management

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation

NIST SP 800-190 · 2 controls

  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security

OWASP ASVS · 2 controls

OWASP MASVS · 2 controls

  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.3 Network Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

  • CAT-D3-1 Preventative controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • NISTPF-5 Protect-P Access Control (PR.AC-P)

NIST SP 1800-32 · 1 control

  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 88 it maps to, and the evidence behind each claim, over MCP and REST.